HIGH7.5CVE-2026-54283Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS >= 0.4.1, < 1.3.1
HIGH7.5CVE-2026-54283Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS >= 0.4.1, < 1.3.1
HIGH7.5CVE-2026-48818Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows from 0, < 1.1.0
HIGH7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
from 0, < 1.1.0
HIGH7.5Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
>= 0.39.0, < 0.49.1
HIGH7.5Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
>= 0.39.0, < 0.49.1
HIGH7.5MultipartParser denial of service with too many fields or files
from 0, < 0.25.0
MEDIUM6.5BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks
from 0, < 1.0.1
MEDIUM5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
from 0, < 1.1.0
MEDIUM5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
from 0, < 1.1.0
MEDIUM5.3Starlette has possible denial-of-service vector when parsing large files in multipart forms
from 0, < 0.47.2
MEDIUM5.3Starlette has possible denial-of-service vector when parsing large files in multipart forms
from 0, < 0.47.2
LOW3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
from 0, < 1.3.0
LOW3.7Starlette has Path Traversal vulnerability in StaticFiles
>= 0.13.5, < 0.27.0
NONE0.0Starlette Denial of service (DoS) via multipart/form-data
from 0, < 0.40.0
NONE0.0Starlette Denial of service (DoS) via multipart/form-data
from 0, < 0.40.0